[Devel] [PATCH vz10 22/24] dm-qcow2: fix ALLOW_ERROR_INJECTION class on qcow2_alloc_delta (ERRNO not NULL)

Pavel Tikhomirov ptikhomirov at virtuozzo.com
Fri Jul 24 18:28:31 MSK 2026


Reviewed-by: Pavel Tikhomirov <ptikhomirov at virtuozzo.com>

On 7/6/26 13:00, Konstantin Khorenko wrote:
> qcow2_alloc_delta() returns a valid pointer or ERR_PTR(-ENOMEM); it never
> returns NULL, and its only caller qcow2_ctr() checks IS_ERR() only, then
> dereferences the result (qcow2->img_id = i). It was annotated
> ALLOW_ERROR_INJECTION(..., NULL), whose default injected return value is 0
> (NULL), which slips past the IS_ERR() check and NULL-derefs. Use ERRNO
> (error pointers only), matching the function's contract and the caller's
> handling. Same class of bug as the dm-ploop ploop_get_delta_file fix.
> 
> Fixes: 538ef4c12f46 ("dm-qcow2: Enable injection fault")
> Feature: dm-qcow2: block device over QCOW2 files driver
> https://virtuozzo.atlassian.net/browse/VSTOR-137234
> Signed-off-by: Konstantin Khorenko <khorenko at virtuozzo.com>
> ---
>  drivers/md/dm-qcow2-target.c | 2 +-
>  1 file changed, 1 insertion(+), 1 deletion(-)
> 
> diff --git a/drivers/md/dm-qcow2-target.c b/drivers/md/dm-qcow2-target.c
> index 3f65897ce9da..de1fb628735b 100644
> --- a/drivers/md/dm-qcow2-target.c
> +++ b/drivers/md/dm-qcow2-target.c
> @@ -678,7 +678,7 @@ static struct qcow2 *qcow2_alloc_delta(struct qcow2_target *tgt, struct qcow2 *u
>  
>  	return qcow2;
>  }
> -ALLOW_ERROR_INJECTION(qcow2_alloc_delta, NULL);
> +ALLOW_ERROR_INJECTION(qcow2_alloc_delta, ERRNO);
>  
>  static int qcow2_attach_file(struct dm_target *ti, struct qcow2_target *tgt,
>  			     struct qcow2 *qcow2, int fd)

-- 
Best regards, Pavel Tikhomirov
Senior Software Developer, Virtuozzo.



More information about the Devel mailing list